The California Air Resources Board expects the first scope 1 and 2 emissions reports under SB 253 in 2026 from every US company with more than $1 billion in revenue doing business in the state. Administrative penalties for non-filing run up to $500,000 per entity per year.
| ESG Risk Assessment Template: Key Takeaways |
| The California Air Resources Board expects first scope 1 and 2 emissions reports under SB 253 in 2026 from companies over $1 billion in revenue, with penalties up to $500,000 per entity per year. |
| The free Excel template carries four tabs: instructions, a 30-risk ESG library, 5×5 scoring scales, and a formula-driven register with traffic-light banding. |
| Every risk gets two materiality ratings: financial (effect on enterprise value) and impact (effect on people and environment). High on either axis keeps it on the register. |
| The WEF Global Risks Report 2026 puts extreme weather, biodiversity loss, and ecosystem collapse as the top three risks on the 10-year horizon: all environmental. |
| Governance risks like greenwashing now carry regulatory teeth through the FTC Green Guides, so unsupported claims belong on the register beside emissions exposures. |
| Score with the same 1-5 anchors used in enterprise risk assessments so ESG exposures compete for treatment budget on equal terms with every other risk. |
That deadline has changed what an ESG risk assessment template needs to be. A questionnaire about values no longer cuts it: risk managers need a scoring workbook that treats environmental, social, and governance exposures with the same rigor as the rest of the risk assessment library.
The free ESG risk assessment template below does exactly that. It seeds 30 common ESG risks, scores them on 5×5 likelihood and impact scales anchored to ISO 31000 practice, and adds the double materiality ratings that newer disclosure regimes assume you have.
Download the ESG Risk Assessment Template (Excel)
The file is ESG risk assessment template, a free ESG risk assessment template you can adapt, with blue input cells, locked formula columns, and a worked example in the first register row. It follows the same conventions as our risk heat map template and the RCSA template, so the three workbooks feel like one toolkit.
| Workbook tab | What it does |
| How to Use | Six setup steps plus the input legend, so a colleague can run it without a briefing |
| Scoring Scales | 1-5 likelihood and impact anchors, and the H/M/L materiality band definitions |
| ESG Risk Library | 30 seeded risks: 10 environmental, 10 social, 10 governance, each with typical data sources |
| ESG Risk Register | The working sheet: dropdowns, score formula, HIGH/MEDIUM/LOW banding with traffic-light shading |
Start the ESG risk assessment template in the library rather than a blank page. Marking which of the 30 risks apply takes an hour with the right people in the room, and that hour surfaces the operational specifics (sites, suppliers, contracts) that make the register yours instead of generic.
In the ESG risk assessment template, the first register row ships as a worked example: an SB 253 compliance risk scored 4 by 4, banded HIGH, with an owner and treatment already written. Study how it uses the columns, then overwrite it with your own most pressing exposure so the format carries forward correctly.
What an ESG Risk Assessment Actually Scores
Strip away the acronym and you are scoring three families of exposure through one register and one set of scales. The categories differ sharply in data sources and natural owners, which is why assessments fail whenever a single function tries to score all three alone.
| Category | What belongs here | Where the data lives |
| Environmental | Emissions and carbon pricing, extreme weather, water stress, waste rules, stranded assets | GHG inventories, EPA figures, insurer models |
| Social | Labor practices, health and safety, privacy, product safety, community relations | OSHA logs, supplier audits, HR and breach data |
| Governance | Board oversight, greenwashing, corruption, data assurance, AI governance | Board matrices, audit findings, proxy filings |
The long-term weighting between the three families is not close. The WEF Global Risks Report 2026 ranks extreme weather, biodiversity loss, and ecosystem collapse as the top three risks on the 10-year horizon, and extreme weather already sits third for the immediate year at 8 percent of respondents.
Governance deserves more respect than it usually gets in ESG scoring. Unsupported green claims now draw scrutiny under the FTC Green Guides, and a greenwashing finding damages both the E scores you reported and the credibility of everything else on the register.
The Regulatory Drivers Behind ESG Risk Assessment in 2026
US obligations arrived by a side door: state law and foreign regimes reaching US subsidiaries, rather than one clean federal rule. The table maps what actually binds as of mid-2026, because scoring regulatory risk credibly starts with knowing precisely which regime touches your revenue footprint.
| Regime | Who it reaches | What it requires |
| California SB 253 | Over $1B revenue, doing business in CA | Scope 1 and 2 emissions reports from 2026; scope 3 anticipated 2027 |
| California SB 261 | Over $500M revenue, doing business in CA | Biennial climate-related financial risk reports |
| SEC climate rule | US public companies | Adopted 2024, now stalled in litigation; monitor rather than ignore |
| ISSB S1 and S2 | Voluntary US baseline | Sustainability and climate disclosure standards investors increasingly request |
| EU CSRD | US firms with large EU operations | Double materiality reporting through European subsidiaries |

Figure 1. SB 253 in four numbers. CARB has proposed shifting the first deadline from August 10 to November 10, 2026.
Track the moving parts without rebuilding your register every quarter: score the regulatory risk once, then adjust likelihood as rules land. Our SEC climate disclosure analysis covers the stalled federal rule, and the ISSB versus CSRD comparison untangles which standard a multinational actually answers to.
Standards bodies matter for the template’s design too, because every disclosure regime borrows its definitions from somewhere. ISSB standards absorbed the SASB standards and TCFD framework, while GRI still anchors impact reporting. The template’s materiality columns map to that split deliberately.
How to Use the ESG Risk Assessment Template Step by Step
Score ESG Risks With the 5×5 Scales
Rate likelihood and impact from the anchored scales, never from gut feel: rating 3 means possible within two to five years with sector precedent, and impact 4 means 3 to 5 percent of revenue or an enforcement action. The register multiplies the two and bands the product HIGH at 15 or above.
Anchors keep three functions honest at the same time. Sustainability teams tend to score environmental risks high, legal teams quietly inflate governance, and operations discounts social exposure it lives with daily. Shared definitions from qualitative and quantitative practice force the debate onto evidence instead of enthusiasm.
Apply Double Materiality in the ESG Risk Assessment
Every risk then gets two H/M/L ratings. Financial materiality asks whether the exposure could move enterprise value; impact materiality asks whether it harms people or environment regardless of the balance sheet. The COSO ERM guidance treats this dual lens as the bridge between sustainability teams and risk functions.

Figure 2. High on either axis keeps a risk on the register; the top-right quadrant gets treatment plans and disclosure.
In the ESG risk assessment template, the quadrant placement then drives the whole downstream workflow. Top-right risks get treatment actions and disclosure, single-axis risks get monitoring with a documented rationale for the lighter touch, and bottom-left risks get parked with a review date so nothing silently disappears from governance view.
Turn the ESG Register Into Treatment and Reporting
Inside the ESG risk assessment template, assign one named owner per risk, record the controls that already exist, and write treatment actions with dates. Quarterly, re-score anything whose driver moved: a new climate transition analysis, a supplier audit finding, or a regulation clearing its comment period.
Feed the outputs upward rather than letting the register become its own destination. HIGH-band risks belong in the enterprise register beside cyber and credit exposures, and the scoring trail gives your risk management policy the evidence layer auditors ask for first.
Board reporting closes the loop each quarter. A one-page extract showing the HIGH band, movement since last quarter, and treatment status answers most director questions before they are asked, and it builds the paper trail that proves oversight if a disclosure is ever challenged.
ESG Risk Examples Worth Scoring First
Some exposures earn a place on almost every US register regardless of sector. These six recur across the assessments we run, and each one pairs with a data source you probably already hold, so scoring them is an afternoon of work rather than a project.
| Risk | Why it scores high in 2026 | First data source |
| Disclosure non-compliance | SB 253 and SB 261 deadlines with penalty exposure | Legal register, CARB guidance |
| Extreme weather disruption | Top-three WEF risk on both horizons | FEMA maps, insurer models |
| Supply chain labor practices | Customer contracts now pass through audit rights | Supplier audits, grievance logs |
| Greenwashing claims | FTC scrutiny plus private litigation | Marketing claims review |
| ESG data failing assurance | Reported figures increasingly need verification | Data lineage, internal audit |
| Ungoverned AI decisions | Governance regimes now name algorithmic risk | Model inventory, AI policy |
Rating agencies already score you on much of this list whether you assess it internally or not. MSCI and Sustainalytics ratings move capital, and CDP questionnaires arrive from customers, so an internal register that anticipates their questions is cheap defense.
Seven Mistakes That Undermine ESG Risk Assessments
Most weak ESG risk assessments share the same handful of design flaws rather than bad data or bad intent. Each mistake below has a countermeasure already wired into the template’s structure, so avoiding them costs configuration discipline rather than new tooling or headcount.
| Mistake | What it looks like | What to do instead |
| Scoring values, not risks | A questionnaire about commitments | Score likelihood and impact of concrete exposures |
| One function scores everything | Sustainability rates governance risk | Three-lens workshop: operations, HR/legal, finance |
| Single materiality only | Balance-sheet lens misses harm-based exposure | Rate both materiality axes on every risk |
| Unanchored 1-5 ratings | Every risk lands at 3×3 | Use the Scoring Scales tab definitions verbatim |
| Register never re-scored | 2024 scores defending 2026 decisions | Quarterly refresh triggered by driver changes |
| ESG kept separate from ERM | Parallel register nobody funds | Promote HIGH bands into the enterprise register |
| No evidence trail | Scores with no data source cited | Library tab names a source for every seeded risk |
Frequently Asked Questions About the ESG Risk Assessment Template
What is an ESG risk assessment template?
An ESG risk assessment template is a structured workbook for identifying, scoring, and treating environmental, social, and governance risks. This one uses Excel with a 30-risk library, 5×5 likelihood and impact scales, double materiality ratings, and a formula-driven register that bands each risk HIGH, MEDIUM, or LOW automatically.
Is the ESG risk assessment template really free?
Yes: download the ESG risk assessment template, adapt the scales and library to your operations, and use it commercially without an email gate or license fee. The workbook ships with everything unlocked. If you need help calibrating it to a specific regulatory footprint, that is consulting work we offer separately.
How is an ESG risk assessment different from a standard risk assessment?
The mechanics are identical: likelihood times impact against anchored scales. The differences are the second materiality axis, the three-category taxonomy, and data sources that sit outside the risk function, from GHG inventories to supplier audits. Our ESG risk management guide covers the surrounding program.
Who should complete the ESG risk assessment template?
A risk manager should facilitate, but never score alone. The workable minimum is one workshop with operations or sustainability for environmental risks, HR and legal for social, and finance plus the general counsel for governance. Board-level review follows once the register carries scores and owners.
Does the ESG risk assessment template cover SB 253 and CSRD?
The library seeds disclosure non-compliance as a scored risk covering SB 253, SB 261, and CSRD exposure, and the materiality columns mirror the double materiality logic CSRD formalized. The template is an assessment tool, though: actual report preparation needs ESG reporting software or advisors.
How often should the ESG risk assessment be updated?
Re-score quarterly for HIGH-band risks and semi-annually for the rest, with an immediate refresh when a driver moves: a new regulation clearing litigation, an acquisition, or a supplier failure. A full re-run of the library scan belongs in the annual planning cycle.
What ESG risks should a smaller company assess first?
Start with the exposures your customers and lenders already ask about: supply chain labor practices, data privacy, workforce safety, and energy costs. Smaller firms rarely trip disclosure thresholds directly, but they inherit them through contracts when a large customer needs supplier data for its own scope 3 reporting.
Can the ESG risk assessment template feed our enterprise risk register?
That is the intended design. HIGH-band ESG risks should promote directly into the enterprise register with their scores intact, competing for treatment budget beside every other exposure. Keeping ESG in a parallel register that never meets the GRC framework is mistake six in the table above.
Where ESG Risk Assessment Is Heading After 2026
Scope 3 is the next cliff on the calendar. CARB anticipates value-chain emissions reporting from 2027, which converts supplier data quality from a procurement nicety into a regulated compliance input, and the carbon accounting platforms that automate it are consolidating fast.
Assurance is tightening in parallel. Reported ESG figures increasingly face limited assurance on the way to reasonable assurance, so the evidence trail your register keeps (sources, scoring rationale, review dates) becomes audit workpaper rather than good practice. EPA emissions data and verified inventories anchor the numbers regulators check first.
Investor pressure has not waited for regulators either. Signatories to the Principles for Responsible Investment manage assets in the tens of trillions, and their due diligence questionnaires reach private companies no disclosure law touches. Geopolitics keeps folding in as well, as the geopolitical risk guide and rising AI governance expectations both show.
Infographic: ESG Risks Compared Side by Side

Figure 3. Three lenses, one register: the same scoring discipline applied to E, S, and G exposures.
Put Your ESG Risk Assessment on Defensible Ground
Download the template, run the first workshop, and see where the scores land. When the register raises questions the workbook cannot answer, from CSRD scoping to assurance readiness, our services cover ESG risk calibration, or reach out directly and we will look at your register together. The climate risk assessment guide and climate KRI examples make useful next reads.
Download it here ESG risk assessment template

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.